Three IAM implementation firms are bidding on your rollout. How do you tell them apart before you sign?

The way this choice goes wrong shows up in month six, not at signing: the architects who pitched are not the engineers on your keyboard, and the control mapping your assessor asks for was never written into the statement of work. Three kinds of firms will bid on this project, and their pitches will sound almost identical for the first thirty minutes: a global systems integrator, a boutique identity specialist, and an identity product vendor’s own services arm. What separates them is not the pitch, it is four things you can verify before you sign a statement of work: a named delivery record at your user count and in your cloud, an engineer roster you can meet, a control-family mapping they will show you in the first meeting, and a written statement of what they have not done. Each class of firm fails in a different place, and the sections below walk through where. Almost every published “top IAM firms” list ranks identity products rather than firms, which is a different question; in a regulated sector the product is the smaller half of the decision, because the artifacts an assessor tests are produced by the implementation firm: the control mapping, the Conditional Access policy set, the access review evidence, and the audit log retention design.

Why most “top IAM firms” lists answer a different question

The lists rank identity platforms on capability. That is a useful exercise and it is not the question a VP of IT in a regulated organization is asking. You are asking who will stand next to you in the assessment.

Microsoft publishes the platform capability matrix openly, so any competent firm can read it. What no vendor page prints is which capability sits behind which license, which one is missing in your cloud, and which one silently stops working when a subscription lapses. Those three facts decide whether your program produces evidence or produces a finding.

A worked example. Lifecycle Workflows, the feature most joiner-mover-leaver designs depend on, is not included in Microsoft Entra ID P2. Microsoft’s licensing reference shows it only under Microsoft Entra ID Governance and Microsoft Entra Suite. The same reference, Entra ID Governance licensing fundamentals, states that “no new Identity Governance and Administration (IGA) features or capabilities will be added to the Microsoft Entra ID P2 SKU.” A firm that scoped your automated deprovisioning against a P2 estate has scoped a control you cannot enforce.

The three classes of firm you are choosing between

Shortlists in this category mix three different business models, and comparing them on a single ranking hides the thing that decides your outcome.

The global systems integrator

Deep bench, every sector, every cloud, and a name your board already recognizes earns its premium only when the program spans continents or when political cover matters more than delivery velocity; outside those two conditions the premium buys recognition, not outcomes. The failure mode is staffing: the senior architects in the pitch are not the engineers on your keyboard in month six, and the identity workstream is one of forty inside a larger program. Test it with the roster question below and ask for the answer in writing, with names and start dates.

The boutique identity specialist

Genuine depth in identity, concentrated in one product, and the fastest class to get an identity design on paper. Where it breaks is the boundary: identity in a regulated Microsoft estate does not stop at the identity provider. It runs into log retention, Microsoft Purview, Azure Policy, the data classification your assessor tests, and the evidence chain that has to survive an audit two years from now. Ask a specialist to show you the design one layer past the identity provider. If the answer is that another vendor owns that layer, you are buying an integration risk along with the design.

The product vendor’s own services arm

The fastest path to that vendor’s product working exactly as designed, delivered by people who know the roadmap before you do. The constraint is structural rather than a question of competence: a services organization inside a product company is not positioned to tell you its own product is the wrong fit for your tenant, your cloud or your control set. That is the single most valuable sentence a firm can say to you during evaluation, and it is the one this class is least free to say.

Where i3solutions sits in that frame

i3solutions is a Microsoft Systems Integrator with experience implementing identity and access management solutions for enterprises in regulated industries. i3solutions has deep experience implementing identity governance for enterprises in aerospace and defense manufacturing, financial services, and healthcare, including environments with CMMC and ITAR obligations. i3solutions delivers its full service portfolio into the healthcare vertical exactly as it does into defense manufacturing and finance, including identity work with Okta and Entra ID, AI work, Power Platform, and Dynamics 365 integration. The broader identity and access management practice this firm-selection question sits inside is described in Establish Identity as a Governed Enterprise Capability.

On the third class specifically, the honest disclosure is that we are a Microsoft-centric firm and you should price that in. What we do about it is run the comparison rather than assume the answer: i3solutions runs comparative platform-selection evaluations for clients, recommending among IAM platforms for hybrid estates and among workflow automation platforms against SOC 2 and HIPAA, rather than only implementing the Microsoft option. i3solutions regularly delivers Okta to Microsoft Entra ID migrations for enterprises, detailed in How Do I Hire Consultants to Migrate Us Off Okta Onto Microsoft Entra ID Without Breaking Access?. The same evaluation that recommends one of those platforms is the one that can recommend staying put. If your evaluation is still open on the platform itself rather than the firm, start with Which IAM Platforms Fit a Complex Hybrid Enterprise: How to Decide, say so on the first call, and we will run that comparison first.

The license math a regulated tenant actually faces

List prices below are Microsoft’s own, published on the Microsoft Entra plans and pricing page and read there on 11 September 2026, with annual commitment. Microsoft changes list prices, so re-read that page before you build a budget on it.

Two counting rules cost more money than the unit price does, and both are worked through in Microsoft’s Entra ID Governance licensing fundamentals reference, which is also the source for the capability table this section summarizes. The buyer’s-guide counterpart to this license math is Microsoft Entra ID Governance for Regulated Enterprises: Product Scope, Licensing, and Audit-Defensible Implementation.

Entitlement management is licensed on who can request, not who does. Microsoft’s worked example: a policy that lets all 2,000 employees request a set of access packages requires 2,000 licenses, even though only 150 employees requested anything (Entra ID Governance licensing fundamentals).

Access reviews license the reviewers and the reviewed. Microsoft’s worked example: a review of a 75-member group with one group owner as reviewer requires 76 licenses (Entra ID Governance licensing fundamentals). A 500-member group with three owners as reviewers requires 503 (Entra ID Governance licensing fundamentals).

If a firm hands you a governance design without a per-capability seat count built on those two rules, they have not costed your program. They have costed a demo. All three classes can produce a capability diagram, and only some of them will produce the seat count behind it.

Four things to verify before you shortlist a firm

1. A delivery record at your user count, in your cloud

Ask for the user count, the application count, and the cloud. Government community cloud, GCC High and Department of Defense environments are not the commercial tenant with a different logo. On Microsoft’s Entra feature availability in Azure for US Government reference, Microsoft Entra ID Governance is available in GCC, GCC High and DoD, and Microsoft Entra Workload Identities Premium is available in Azure for US Government. Several things are not. Microsoft Entra threat intelligence as a risk detection is listed unavailable, and the My Staff delegated user management portal is listed unavailable. HR-driven provisioning is listed as partial. A firm that has only delivered commercially will discover these in your sprint, at your cost.

The i3solutions answer to that question: We manage GCC High migrations end-to-end: from eligibility validation and licensing coordination with your AOS-G supplier through identity architecture, data migration, security baseline configuration, and post-migration governance.

2. An engineer roster you can meet before signing

Ask who is actually on the keyboard, where they sit, and whether they will still be on the engagement in month six. i3solutions governs identity and access for regulated Microsoft estates with senior, U.S.-based engineers and leaves an audit-defensible record. Ask any firm the same question and treat anything short of names, start dates and a written commitment as a red flag; the global integrator class most often answers this question with a logo slide instead.

3. A control-family mapping, shown in the first meeting

Identity work in a regulated sector is evidence work. i3solutions maps your Microsoft environment against CMMC Level 2 (the 110 controls of NIST SP 800-171 Rev 2), HIPAA administrative safeguards, and SOC 2 access control frameworks, producing audit-ready documentation that satisfies assessors, not just internal IT teams. The i3solutions Federal Compliance Assessment evaluates a client tenant against NIST SP 800-53 and CMMC using automated tenant configuration scripts and a 42-point security checklist; on the control that most often decides that assessment, see MFA and NIST SP 800-53: Your Baseline Decides, Not the Catalog. Ask for the control mapping before the contract, not after it.

4. A written statement of what they have not done

A firm that claims every sector and every boundary is describing a sales territory, not a record. Ours is in the section below. If your requirement is narrower than a shortlist and you already know the environment is government contracting, the sibling question is answered on hiring an IAM implementation firm for a government contracting environment.

Where these programs break down in a regulated tenant

Log retention is shorter than your framework requires, and P2 does not fix it. Microsoft’s Entra data retention reference gives audit logs and sign-in logs seven days on Entra ID Free and 30 days on both P1 and P2. Paying for P2 buys you Privileged Identity Management, not longer logs. Risky sign-ins is the one report that stretches, to 90 days on P2. If your control set expects a longer window, the design has to route Entra logs to an Azure storage account through Azure Monitor, or retain them through Microsoft Purview Audit (Premium), which needs Microsoft 365 E5, Office 365 E5, the Microsoft Purview Suite, or the E5 eDiscovery and Audit add-on. The i3solutions delivery standard: Audit-ready logging for external teams requires capturing user activity, data access, configuration changes, and privilege escalations with 90-day minimum retention.

Retention changes are not retroactive. Microsoft states it plainly: upgrading from Free to P1 or P2 surfaces only data still inside the free seven-day window. Data already expired cannot be recovered unless it was archived. A tenant that upgrades in month three to satisfy an audit finding has not recovered months one and two.

Conditional Access does not fail loudly when licensing lapses. Microsoft documents the graceful state: when the required licenses expire, policies are not automatically disabled or deleted. You can view and delete remaining policies, but you cannot update them. Your enforcement keeps running while your ability to change it is gone. That is a reasonable design choice by Microsoft and a governance trap for anyone who does not know it.

Privileged Identity Management does the opposite. If the P2 or Entra ID Governance license expires, eligible role assignments are removed, active time-bound assignments become permanent, ongoing access reviews of Microsoft Entra roles end, and PIM configuration settings are removed. Permanent role assignments are unaffected. The just-in-time control collapses into standing privilege, which is the exact posture the control existed to prevent.

The firm’s own access gets scoped once, in production, and never in the lower environments. That is the pattern, and it is where the model leaks. From i3solutions delivery experience: External Microsoft teams typically require access to 3-7 different environments, dev, test, staging, production, each containing varying levels of sensitive data and business-critical configurations. Ask a candidate firm how it holds itself to your access model across all of them, not just production. i3solutions engineers work inside the client’s own tenant as Microsoft Entra B2B guest accounts with scoped Dataverse security roles, not from an i3solutions-owned tenant. The i3solutions delivery standard: Break-glass production access for external teams should be limited to under 4 hours with mandatory security team approval and real-time monitoring.

The migration is longer than the shortlist conversation implies. Complex environments with hundreds of app federations, custom Okta workflows, or external identity federation requirements may require 6 to 12 months and phased coexistence architecture. That range is i3solutions’ own delivery experience, not a vendor or analyst figure. A firm quoting a fixed short identity cutover against an estate like that is quoting a phase, not the program.

What an assessor-ready early rollout looks like

The sequence matters more than the tooling: license and capability truth first, then a report-only Conditional Access baseline, then the log retention design, then governance enforcement last.

Weeks 1 to 2, the license and capability truth. In the Microsoft Entra admin center at entra.microsoft.com, under Billing then Licenses then Licensed features, establish which service plans the tenant actually holds. The specific thing to look for is whether the tenant carries AAD_PREMIUM or AAD_PREMIUM_P2, because Microsoft Entra ID Governance requires one of them and Lifecycle Workflows is only available under Governance or the Entra Suite. Then map every capability you intend to enforce to the license that carries it, and put the seat count from the two counting rules above against each one. The deliverable at the end of week two is that capability-to-license map. It is the artifact that stops a deprovisioning design landing on a P2 estate that cannot run Lifecycle Workflows, which is the single most common way this sequence fails. Senior Microsoft specialists from i3solutions typically embed in the client’s team within two to four weeks of engagement start.

Weeks 2 to 5, the Conditional Access baseline in report-only. Per Microsoft’s Conditional Access overview, it lives in the Microsoft Entra admin center under Entra ID then Conditional Access, is visible to anyone with at least the Security Reader role, and requires Microsoft Entra ID P1. The Overview page shows how many policies are enabled versus report-only; the Coverage tab shows applications with and without policy coverage over the past seven days. Run the new baseline in report-only and read the Coverage tab before you enforce anything. Risk-based policies on sign-in risk and user risk need Microsoft Entra ID Protection, which is a P2 feature, so a P1 tenant cannot build them regardless of design intent.

Weeks 4 to 8, the log retention design. Decide the archive path before the assessor asks, and decide it on the licenses the tenant already holds: Purview Audit (Premium) needs one of the E5-class licenses named above, so a tenant without one either buys it or routes Entra logs to an Azure storage account through Azure Monitor.

The closing phase, governance enforcement and the evidence chain. Access reviews, entitlement management with separation of duties, and PIM for the privileged roles, with the seat counts from the two counting rules above. i3solutions maps governance to named control families, enforces it in the platform through Entra ID, Purview, and Azure Policy, and evidences it continuously rather than reconstructing it at audit. The delivery record behind those claims, and the boundary it does not cross, is set out in the next section.

Where i3solutions fits, and where it does not

The record. For a US state government, i3solutions designed, implemented and maintained the Okta architecture behind a network of over 70,000 users dispersed across various departments and locations. That identity modernization included multifactor authentication as well as single sign-on. On application coverage, i3solutions utilized various methods, including the Okta Integrated Network and manual integration, to seamlessly incorporate over 30 applications into the authentication framework.

A second client is a nonprofit government consulting firm. Implementing Okta SSO with MFA achieved 95% enrollment across 4,000 users within 60 days, closing critical authentication gaps and reducing breach risk exposure valued at over $1M annually. By consolidating logins from three systems into one and enabling Okta Single Sign-On (SSO) with 95% MFA adoption, the firm reduced password reset tickets by 40%, eliminating more than 4,000 annual IT support requests and saving approximately $100K in helpdesk time each year.

At provisioning scale: For a global professional services firm, i3solutions unified siloed systems and automated provisioning across them for 125,000 users, and an integration of that size holds together precisely because systems connect through a managed integration layer rather than a web of direct links. i3solutions delivered an Entra ID integration engagement for a global consumer goods manufacturer. i3solutions installs and helps configure applications inside IL4 and IL6 government cloud environments and other government networks. i3solutions has completed more than 600 Microsoft platform implementations. The identity work sits inside our Microsoft integration services practice.

The limit, stated plainly. The state government work is state government. It is not federal. i3solutions has not delivered an identity and access management implementation inside a federal agency authorization boundary and does not present the work above as if it had. If your requirement is a federal ATO-boundary IAM delivery record, say so on the first call and we will tell you whether another firm is the better fit. Scot Johnson co-founded i3solutions 30 years ago with a focus on expert-led delivery, strategic advisory, and complex Microsoft-centered solutions for organizations where technology decisions carry operational, financial, and mission risk. A firm-selection page that overstates the record is useless to you and dangerous to us.

What an engagement costs

Directional bands, so you can size a budget line before the first call.

  • A CMMC Level 2 implementation for a defense contractor with a defined CUI boundary typically ranges from $45,000 to $75,000, covering the Compliance Manager baseline assessment, Conditional Access redesign, DLP policy build and testing, Purview Audit Premium configuration, and post-implementation documentation.
  • Microsoft 365 compliance consulting for regulated enterprises ranges from $35,000 to $120,000 or more depending on the framework, the number of in-scope systems, and the current tenant configuration.
  • For embedded senior capacity: Typical engagement ranges land at $28,000 to $48,000 per specialist per month for senior US-based Microsoft specialists with named platform depth (SharePoint, Power Platform, Microsoft 365 compliance, Azure security, Dataverse, .NET enterprise integration) and compliance literacy in CMMC 2.0 Level 2, HIPAA Security Rule, NIST 800-171 Rev 3, SOC 2, or DFARS 252.204-7012.

These are engagement bands, not license costs. The Microsoft license figures earlier in this page are Microsoft’s published list prices and are paid to Microsoft.

Frequently asked questions

Should we choose the platform or the firm first?

The firm first, in a regulated sector. The platform decision is reversible over a multi-year horizon and is heavily constrained by what your tenant already holds. The evidence chain your assessor tests is produced by the firm, and a weak one leaves you re-doing the mapping with a second vendor while the first vendor’s design is still in production.

How do the three classes of IAM firm actually differ?

They differ in what they are structurally free to tell you. A global systems integrator brings bench depth and board recognition and is weakest on which named engineers stay through month six. A boutique identity specialist brings product depth and is weakest one layer past the identity provider, where log retention, Microsoft Purview and Azure Policy decide whether your evidence chain holds. A product vendor’s services arm is fastest to a working deployment of its own product and is least able to tell you that product is the wrong fit. Run the same four checks against all three (a delivery record at your user count and in your cloud, an engineer roster you can meet, a control-family mapping shown in the first meeting, and a written statement of what the firm has not done), and treat a firm that cannot answer one of them plainly as disqualified.

Should the firm’s scope cover privileged access management as well as identity governance?

It should, and the statement of work should say so, because the two are scoped by different teams and priced separately. Identity governance covers who has standing access and how it is reviewed: entitlement management, access reviews, joiner-mover-leaver automation. Privileged access covers what happens when someone needs elevated rights, which in a Microsoft estate is Privileged Identity Management and its just-in-time elevation. An assessor tests both. A scope that governs standing access but leaves privileged elevation to a separate future phase produces an evidence gap, with no record of just-in-time elevation, on exactly the accounts your auditor examines first.

Does Microsoft Entra ID P2 cover identity governance?

Partly, and less each year. P2 carries Privileged Identity Management, access reviews and entitlement management. It does not carry Lifecycle Workflows, account discovery, cross-cloud synchronization, or machine-learning assisted access certifications, all of which Microsoft lists under Microsoft Entra ID Governance or Microsoft Entra Suite. Microsoft’s licensing reference also states that no new IGA features will be added to the P2 SKU (Entra ID Governance licensing fundamentals), so the gap widens rather than closes.

Can we run the same IAM design in GCC High or DoD that we run commercially?

Mostly, with named exceptions you should design around rather than discover. Microsoft Entra ID Governance, Conditional Access, PIM, access reviews and entitlement management are listed available in Azure for US Government. Microsoft Entra threat intelligence as a risk detection and the My Staff delegated user management portal are listed unavailable, and HR-driven provisioning is listed as partial.

How long do Microsoft Entra logs last?

Audit logs and sign-in logs are retained seven days on Entra ID Free and 30 days on both P1 and P2 (Entra data retention reference). Risky sign-ins reaches 90 days on P2 (Entra data retention reference). Longer retention requires routing to an Azure storage account through Azure Monitor or retaining through Microsoft Purview Audit (Premium). Retention changes are not retroactive.

What happens to our access controls if a license lapses?

They diverge, which is the part worth knowing in advance. Conditional Access policies keep enforcing but become read-only, so you can view and delete them but not update them. Privileged Identity Management removes eligible role assignments, converts active time-bound assignments to permanent, and ends ongoing access reviews of Microsoft Entra roles.

Is i3solutions a Microsoft partner?

Yes. i3solutions is a Microsoft Solutions Partner and has completed more than 600 Microsoft platform implementations.

A scoping conversation against your own tenant

If you are building the shortlist rather than signing it, the useful next hour is a scoping conversation against your own tenant: which service plans you actually hold, which governance capabilities those licenses carry and which they do not, and what the seat count comes to under the two counting rules above. You leave with the capability-to-license map and the control-family mapping, which is the part your committee and your assessor both ask to see.

Bring your categorization and your framework list, not a feature wish list. If your requirement turns out to be a federal ATO-boundary delivery record, we will say so on that call.

Contact a senior architect